A three-person law firm keeps files as sensitive as a bank with three thousand staff. An accountant with one employee e-mails national registry numbers as often as a hospital does. The GDPR does not care about headcount, and NIS2 looks at the sector, not at the number of desks. Yet almost every vendor sells governance as something for the big customer: a separate licence, an enterprise tier, a minimum number of users.
We think that is upside down. Policy that enforces itself is exactly what a small organisation needs, because nobody there has time to check it by hand. That is why the Governance Center is part of every Canvos plan, from a single user upwards, without an extra module.
What it isOne screen, ten tabs, no exceptions
The Governance Center is the one place where an administrator sets the organisation's policy. Not as a document in a folder, but as rules the platform carries out:
- Sharing policy. External sharing on or off, public links with a mandatory password and a maximum expiry, blocked file types, and optionally administrator approval for every external share.
- E-mail policy. Attachment limits per file and per message, blocked domains and attachment types, a mandatory disclaimer and a compliance BCC.
- Data classification. Labels on files, from Public to Restricted, each defining what is allowed: external sharing, public link, download, e-mail attachment, watermark.
- DLP on content. Rules that do not just look at the file name but inside the document. Belgian national registry numbers, IBANs and card numbers are recognised with their check digits, so a random string of digits does not raise a false alarm. This works in docx, xlsx, pptx and pdf too.
- Retention. Trash, file versions, e-mail, chat, audit log and deleted users, each with its own period. A worker carries it out, every hour.
- Legal hold. A hold on a file: it can no longer be changed, renamed or deleted, with the reason attached.
- Approvals, mobile policy, compliance and events make up the ten.
Where it countsEnforced, not just stored
A setting that only lives in a database is an intention. Governance begins when the rule also applies to people who never saw the setting. That is why Canvos enforces every policy at four points at once:
An example. An employee uploads an export of the staff list to a shared folder. The file is called list.xlsx, harmless enough. The content DLP rule reads the sheet, finds two valid national registry numbers and blocks the upload. The employee sees why. The administrator gets a notification. And it is recorded in the log, with a hash that can no longer be changed.
| Chain | Action | What | Result |
|---|---|---|---|
| #1284 e7c1…9a | upload | list.xlsx national registry number (2x) | Blocked |
| #1283 41f0…2d | share | quote-2026-118.pdf external, awaiting administrator | Approval |
| #1282 c88a…70 | download | lease-contract.pdf Confidential, watermarked | Allowed |
| #1281 0d5e…b3 | legal-hold | case-2024-031/ legal hold: ongoing proceedings | Set |
| #1280 9b12…f4 | to competitor.example blocked domain | Blocked | |
| #1279 77ae…c0 | retention | chat older than 365 d 21 rooms cleaned up | Done |
EvidenceA log you cannot alter, and neither can we
Every event gets a sequence number and a sha256 hash over its content plus the hash of the previous line. Whoever changes or deletes a single line breaks the chain from that point on, and you see it with one click. Every day the platform signs the latest point of the chain with a key that exists for that purpose only. An auditor can recompute it without taking our word for it.
The same facts feed the compliance report. Not a questionnaire someone fills in, but a pdf, csv or xlsx with what actually happened: how many actions, how many blocked, which rules intervened most, whether the chain is intact, and which policy was in force. The monthly report lands in the mailbox of whoever you name.
- Classification active and enforced10 / 10
- DLP rules on content10 / 10
- Public links: password and expiry10 / 10
- Event chain intact10 / 10
- Nextcloud synchronised10 / 10
- Retention configured and running10 / 10
- Mobile: screen protection0 / 5
- Alerts or monthly report configured0 / 5
For comparisonHow Nextcloud does it
Canvos is built on Nextcloud, so we follow closely what Nextcloud itself does here. In August 2026 a preview of Nextcloud Governance appeared: sensitivity labels, retention policies, legal hold, DLP and a Compliance Manager with a score. Eric Burger wrote a thorough, honest review of it (in Dutch), and it is worth reading.
Nextcloud's strongest point is that it sits in the core: the rules apply to every client. Legal hold really does block editing and deletion. That is also why we push our sharing policy and retention into that same core instead of only building on top of it.
The review is just as clear about what is not there yet. Retention did not work on Nextcloud 34 in the tested version. Labels are applied by hand. A document under retention remains editable. There is no retention at team-folder level and no disposition list with approval. And the point that matters most to anyone reading this: Nextcloud Governance is an Enterprise feature, not in the App Store, with a minimum of one hundred users.
| Area | Canvos Governance Center | Nextcloud Governance (preview) |
|---|---|---|
| Available to | every plan, from one user, included | Enterprise, from one hundred users |
| Scope | files, e-mail, chat, mobile | files |
| Enforcement | Canvos, Nextcloud, Euro Office, mobile app | in the Nextcloud core, for all clients |
| DLP | name, type, size, domain, and content with national registry number, IBAN, card number, custom regex | present, not described in detail in the review |
| Retention | per organisation, run by a worker, with a dry run first | per document, two actions; not yet working on NC34 in the tested version |
| Legal hold | per file, with reason, blocked in Canvos and locked in Nextcloud | works, blocks editing and deletion; sits with the user rather than with a role |
| Approval | external shares and DLP hits through a request to the administrator | not described |
| Log | hash chain, signed daily, export CSV, JSON, CEF | not described |
| Report and score | score on facts, report pdf, csv, xlsx, monthly by e-mail | Compliance Manager with score, details unknown |
Nextcloud column based on the review of preview 1.0.1 (August 2026). Nextcloud has announced improvements for coming releases.
The choiceDefault, from one user
We could have put governance in a separate tier. That is what the market is used to, and it is an easy way to raise a price tag. We do not, for a simple reason: the organisations at the greatest risk are precisely the ones that will never buy an enterprise licence. A notary, a GP practice, an architecture firm. They have no compliance officer. They need a platform that knows the rules.
Governance is not a luxury for the large. It is the baseline for anyone who handles other people's data seriously. With us that baseline simply comes included.